Skip to content

chore(deps): bump github.com/sigstore/fulcio from 1.8.5 to 1.8.6 in /operator/tools/operator-sdk#21504

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/operator/tools/operator-sdk/github.com/sigstore/fulcio-1.8.6
Open

chore(deps): bump github.com/sigstore/fulcio from 1.8.5 to 1.8.6 in /operator/tools/operator-sdk#21504
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/operator/tools/operator-sdk/github.com/sigstore/fulcio-1.8.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/sigstore/fulcio from 1.8.5 to 1.8.6.

Release notes

Sourced from github.com/sigstore/fulcio's releases.

v1.8.6

Changelog

  • 378c654f48c3bafdced04ead7010aab2cb4c6ca1 Block cross-host redirects and restrict bearer token to expected host (#2354)
  • 39b48e6a8f2efe1809a1b19b4301666c3fd36667 Include raw subject in certificates (#2307)
  • 80eaed06e911cdfd26dd18f02b8e862f7f6ee453 Update Azure AKS OIDC issuer URL regex (#2266)
  • 001376a50932095cf4b6e65299ed2d29abe83524 add support for new circleci root issuer (#2278)

Thanks for all contributors!

Changelog

Sourced from github.com/sigstore/fulcio's changelog.

v1.8.6

Features

  • Include raw subject in certificates (#2307)
Commits
  • 378c654 Block cross-host redirects and restrict bearer token to expected host (#2354)
  • 7a5d3e3 bump builder image to use go1.26.3 (#2353)
  • a05982e build(deps): bump go.step.sm/crypto from 0.75.0 to 0.81.0 (#2348)
  • dfa63a8 build(deps): bump golang from 313faae to 2d6c802 (#2344)
  • 7b3a344 build(deps): bump google.golang.org/api from 0.279.0 to 0.280.0 (#2349)
  • 9290f7f build(deps): bump the all group with 2 updates (#2350)
  • 423d535 build(deps): bump nginx from 1.31.0 to 1.31.1 in the all group (#2352)
  • 19a3f8e build(deps): bump the all group across 1 directory with 6 updates (#2337)
  • 6b597ce build(deps): bump google.golang.org/api from 0.276.0 to 0.279.0 (#2338)
  • 0d1dc79 build(deps): bump nginx from 1.29.8 to 1.31.0 in the all group (#2342)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added area/operator auto-merge Auto-merge minor and patch version bumps auto-retest PRs with this label will be automatically retested if prow checks fails dependencies Pull requests that update a dependency file labels Jul 1, 2026
@dependabot dependabot Bot requested a review from a team as a code owner July 1, 2026 01:27
@github-actions

github-actions Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

🚀 Build Images Ready

Images are ready for commit c458a2e. To use with deploy scripts:

export MAIN_IMAGE_TAG=4.12.x-373-gc458a2e797

@rhacs-bot

Copy link
Copy Markdown
Contributor

/retest

Bumps [github.com/sigstore/fulcio](https://github.com/sigstore/fulcio) from 1.8.5 to 1.8.6.
- [Release notes](https://github.com/sigstore/fulcio/releases)
- [Changelog](https://github.com/sigstore/fulcio/blob/main/CHANGELOG.md)
- [Commits](sigstore/fulcio@v1.8.5...v1.8.6)

---
updated-dependencies:
- dependency-name: github.com/sigstore/fulcio
  dependency-version: 1.8.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/operator/tools/operator-sdk/github.com/sigstore/fulcio-1.8.6 branch from 808302a to c458a2e Compare July 1, 2026 12:32
@openshift-ci

openshift-ci Bot commented Jul 1, 2026

Copy link
Copy Markdown

@dependabot[bot]: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/gke-qa-e2e-tests c458a2e link false /test gke-qa-e2e-tests
ci/prow/ocp-4-12-scanner-v4-install-tests c458a2e link false /test ocp-4-12-scanner-v4-install-tests
ci/prow/ocp-4-12-qa-e2e-tests c458a2e link false /test ocp-4-12-qa-e2e-tests
ci/prow/ocp-4-21-scanner-v4-install-tests c458a2e link false /test ocp-4-21-scanner-v4-install-tests
ci/prow/ocp-4-22-scanner-v4-install-tests c458a2e link false /test ocp-4-22-scanner-v4-install-tests
ci/prow/ocp-4-22-operator-e2e-tests c458a2e link false /test ocp-4-22-operator-e2e-tests
ci/prow/ocp-4-22-qa-e2e-tests c458a2e link false /test ocp-4-22-qa-e2e-tests
ci/prow/ocp-4-22-nongroovy-e2e-tests c458a2e link false /test ocp-4-22-nongroovy-e2e-tests

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/operator auto-merge Auto-merge minor and patch version bumps auto-retest PRs with this label will be automatically retested if prow checks fails dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant